TavernKeeper Scan Report

bmen25124/SillyTavern-MCP-Client

Commit 04fdfe4 Reviewed

33 material concerns identified.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 33 material 10 low

What this review found

Dependency advisory GHSA-v6h2-p8h4-qcjw applies

Material concern · low confidence

A dependency was flagged for a known security problem, but the supplied evidence does not identify the package or show whether this extension actually uses the affected code.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v6h2-p8h4-qcjw to a dependency declared by this repository.

Contextual assessment: The scanner reports an advisory match in the production lockfile, but package identity, installed version, vulnerable range, reachability, attacker-controlled input, and concrete impact are omitted. The finding cannot be reduced to expected behavior from the available evidence; it requires dependency-level validation.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, then assess whether the vulnerable code is runtime-reachable; update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v6h2-p8h4-qcjw
File role
production
Source
package-lock.json

Dependency advisory GHSA-4x5r-pxfx-6jf8 applies

Material concern · low confidence

A dependency was flagged for a known security problem, but the supplied evidence does not identify the package or show whether this extension actually uses the affected code.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.

Contextual assessment: The scanner reports an advisory match in the production lockfile, but package identity, installed version, vulnerable range, reachability, attacker-controlled input, and concrete impact are omitted. The finding cannot be reduced to expected behavior from the available evidence; it requires dependency-level validation.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, then assess whether the vulnerable code is runtime-reachable; update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4x5r-pxfx-6jf8
File role
production
Source
package-lock.json

Dependency advisory GHSA-fv7c-fp4j-7gwp applies

Material concern · low confidence

A dependency was flagged for a known security problem, but the supplied evidence does not identify the package or show whether this extension actually uses the affected code.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fv7c-fp4j-7gwp to a dependency declared by this repository.

Contextual assessment: The scanner reports an advisory match in the production lockfile, but package identity, installed version, vulnerable range, reachability, attacker-controlled input, and concrete impact are omitted. The finding cannot be reduced to expected behavior from the available evidence; it requires dependency-level validation.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, then assess whether the vulnerable code is runtime-reachable; update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fv7c-fp4j-7gwp
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh29-5h37-fv8m applies

Material concern · low confidence

A dependency was flagged for a known security problem, but the supplied evidence does not identify the package or show whether this extension actually uses the affected code.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh29-5h37-fv8m to a dependency declared by this repository.

Contextual assessment: The scanner reports an advisory match in the production lockfile, but package identity, installed version, vulnerable range, reachability, attacker-controlled input, and concrete impact are omitted. The finding cannot be reduced to expected behavior from the available evidence; it requires dependency-level validation.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, then assess whether the vulnerable code is runtime-reachable; update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh29-5h37-fv8m
File role
production
Source
package-lock.json

Dependency advisory GHSA-qj8w-gfj5-8c6v applies

Material concern · low confidence

A dependency was flagged for a known security problem, but the supplied evidence does not identify the package or show whether this extension actually uses the affected code.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-qj8w-gfj5-8c6v to a dependency declared by this repository.

Contextual assessment: The scanner reports an advisory match in the production lockfile, but package identity, installed version, vulnerable range, reachability, attacker-controlled input, and concrete impact are omitted. The finding cannot be reduced to expected behavior from the available evidence; it requires dependency-level validation.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, then assess whether the vulnerable code is runtime-reachable; update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-qj8w-gfj5-8c6v
File role
production
Source
package-lock.json

Dependency advisory GHSA-5c6j-r48x-rmvq applies

Material concern · low confidence

A dependency was flagged for a known security problem, but the supplied evidence does not identify the package or show whether this extension actually uses the affected code.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-5c6j-r48x-rmvq to a dependency declared by this repository.

Contextual assessment: The scanner reports an advisory match in the production lockfile, but package identity, installed version, vulnerable range, reachability, attacker-controlled input, and concrete impact are omitted. The finding cannot be reduced to expected behavior from the available evidence; it requires dependency-level validation.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, then assess whether the vulnerable code is runtime-reachable; update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-5c6j-r48x-rmvq
File role
production
Source
package-lock.json

JavaScript analysis reported javascript.download-to-execution

Material concern · low confidence

The scanner reports that downloaded data and code execution exist somewhere in the same bundled file, but the supplied excerpt does not show whether they are connected or intentionally used by the MCP feature.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: The candidate is a correlation between a network retrieval primitive and a dynamic code or command execution sink across a generated bundle. The bounded evidence omits the relevant implementations and data-flow edges, so exploitation and intent cannot be confirmed; however, if remote or configurable MCP content reaches execution, it could enable arbitrary actions in the host context.

Impact: high · Exploitability: plausible

Developer action: Provide the unbounded executable sections showing the network request, dynamic execution sink, call sites, and any user disclosure or confirmation flow.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.download-to-execution
File role
generated
Source
dist/index.js:25-1018

Dependency advisory GHSA-v2hh-gcrm-f6hx applies

Material concern · low confidence

A dependency was flagged for a known security problem, but the supplied evidence does not identify the package or show whether this extension actually uses the affected code.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.

Contextual assessment: The scanner reports an advisory match in the production lockfile, but package identity, installed version, vulnerable range, reachability, attacker-controlled input, and concrete impact are omitted. The finding cannot be reduced to expected behavior from the available evidence; it requires dependency-level validation.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, then assess whether the vulnerable code is runtime-reachable; update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v2hh-gcrm-f6hx
File role
production
Source
package-lock.json

Dependency advisory GHSA-968p-4wvh-cqc8 applies

Material concern · low confidence

A dependency was flagged for a known security problem, but the supplied evidence does not identify the package or show whether this extension actually uses the affected code.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-968p-4wvh-cqc8 to a dependency declared by this repository.

Contextual assessment: The scanner reports an advisory match in the production lockfile, but package identity, installed version, vulnerable range, reachability, attacker-controlled input, and concrete impact are omitted. The finding cannot be reduced to expected behavior from the available evidence; it requires dependency-level validation.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, then assess whether the vulnerable code is runtime-reachable; update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-968p-4wvh-cqc8
File role
production
Source
package-lock.json

Dependency advisory GHSA-2g4f-4pwh-qvx6 applies

Material concern · low confidence

A dependency was matched to a published security advisory, but the supplied evidence does not say which dependency or whether this extension actually uses the affected feature.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-2g4f-4pwh-qvx6 to a dependency declared by this repository.

Contextual assessment: The scanner reports advisory GHSA-2g4f-4pwh-qvx6 for a declared dependency, but package identity, installed version, advisory conditions, runtime reachability, and attacker-controlled input are absent. The finding cannot be reduced to a confirmed runtime issue from this evidence alone.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and locked version, then assess whether production code reaches the vulnerable functionality and update it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-2g4f-4pwh-qvx6
File role
production
Source
package-lock.json

Dependency advisory GHSA-v39h-62p7-jpjc applies

Material concern · low confidence

A high-severity dependency warning exists, but the available report omits the package and details needed to determine whether users are exposed.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.

Contextual assessment: The scanner reports advisory GHSA-v39h-62p7-jpjc, yet does not provide the matched package, locked version, vulnerable range, reachable code path, or input/control assumptions. Severity alone does not establish an immediately exploitable production vulnerability.

Impact: high · Exploitability: plausible

Developer action: Identify the affected package and locked version, determine runtime reachability and attacker-controlled inputs, and update or mitigate if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v39h-62p7-jpjc
File role
production
Source
package-lock.json

Dependency advisory GHSA-h67p-54hq-rp68 applies

Material concern · low confidence

The dependency scanner found a possible issue, but it does not reveal enough information to tell whether it affects normal extension use.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-h67p-54hq-rp68 to a dependency declared by this repository.

Contextual assessment: Advisory GHSA-h67p-54hq-rp68 is reported against an unspecified declared dependency. The evidence lacks package/version mapping and runtime reachability, so impact and exploitability remain conditional.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and locked version, then verify reachability and remediate if the vulnerable code is used in production.

Scanner
osv-scanner 2.4.0
Rule
GHSA-h67p-54hq-rp68
File role
production
Source
package-lock.json

Dependency advisory GHSA-q3j6-qgpj-74h6 applies

Material concern · low confidence

A high-severity library warning was reported, but the report does not show which library is involved or how an attacker could trigger it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.

Contextual assessment: The scanner reports GHSA-q3j6-qgpj-74h6 without package identity, installed version, vulnerable behavior, or attacker-input path. This supports remediation triage, not a confirmed immediate-danger conclusion.

Impact: high · Exploitability: plausible

Developer action: Map this advisory to the exact locked package and version, check production reachability, and update or apply the vendor mitigation when relevant.

Scanner
osv-scanner 2.4.0
Rule
GHSA-q3j6-qgpj-74h6
File role
production
Source
package-lock.json

Dependency advisory GHSA-wf6x-7x77-mvgw applies

Material concern · low confidence

This warning may affect users, but the supplied information is too incomplete to establish the practical risk.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-wf6x-7x77-mvgw to a dependency declared by this repository.

Contextual assessment: GHSA-wf6x-7x77-mvgw is reported for an unspecified dependency. No package/version, execution path, trigger, or concrete harm is supplied, preventing a definitive contextual determination.

Impact: high · Exploitability: plausible

Developer action: Identify the affected locked dependency and evaluate whether its vulnerable functionality is reachable from MCP configuration, server responses, or other user-controlled data; remediate if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-wf6x-7x77-mvgw
File role
production
Source
package-lock.json

Dependency advisory GHSA-23c5-xmqv-rm74 applies

Material concern · low confidence

A high-severity dependency issue was flagged, but the evidence does not identify the affected component or show that normal use reaches it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.

Contextual assessment: The advisory GHSA-23c5-xmqv-rm74 is present only as scanner metadata. Missing dependency mapping, version, reachability, and input conditions make a confirmed exploit assessment unavailable.

Impact: high · Exploitability: plausible

Developer action: Determine the matched package and locked version, validate runtime reachability and attacker control, and upgrade or mitigate if the advisory applies.

Scanner
osv-scanner 2.4.0
Rule
GHSA-23c5-xmqv-rm74
File role
production
Source
package-lock.json

Dependency advisory GHSA-3jxr-9vmj-r5cp applies

Material concern · low confidence

The scanner identified a serious possible library problem, but the report omits the facts needed to confirm user exposure.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.

Contextual assessment: GHSA-3jxr-9vmj-r5cp is reported without the affected dependency, installed version, vulnerable code path, or attacker-controlled input. The finding warrants investigation but does not demonstrate malicious behavior or immediate exploitability.

Impact: high · Exploitability: plausible

Developer action: Map the advisory to the exact shipped package/version and assess production reachability before selecting an upgrade or mitigation.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp
File role
production
Source
package-lock.json

Dependency advisory GHSA-v56q-mh7h-f735 applies

Material concern · low confidence

A high-severity dependency advisory was detected, but the supplied evidence does not show which component is affected or whether users can trigger it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v56q-mh7h-f735 to a dependency declared by this repository.

Contextual assessment: The scanner reports GHSA-v56q-mh7h-f735, while package identity, locked version, vulnerable range, runtime reachability, and attacker-input conditions are withheld. Contextual severity therefore remains uncertain.

Impact: high · Exploitability: plausible

Developer action: Identify the affected dependency/version, establish whether production execution can reach the vulnerable code, and remediate if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v56q-mh7h-f735
File role
production
Source
package-lock.json

Dependency advisory GHSA-7p8r-x3mc-p8w7 applies

Material concern · low confidence

A scanner found a known issue in a dependency, but the supplied evidence does not identify the package, version, or whether this extension can trigger it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.

Contextual assessment: The advisory match is high-confidence, but package identity, resolved version, vulnerable range, runtime reachability, attacker-controlled input, and concrete effect are omitted. The lockfile context shown does not support a complete impact assessment.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory applicability, then upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7p8r-x3mc-p8w7
File role
production
Source
package-lock.json

Dependency advisory GHSA-7r86-cg39-jmmj applies

Material concern · low confidence

A scanner found a known issue in a dependency, but the supplied evidence does not show what component is affected or whether users can reach the vulnerable code.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.

Contextual assessment: Only an advisory identifier and generic scanner description are supplied. Dependency identity, resolved version, reachability, input control, and impact are unavailable.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory applicability, then upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7r86-cg39-jmmj
File role
production
Source
package-lock.json

Dependency advisory GHSA-8fgc-7cc6-rx7x applies

Material concern · low confidence

A scanner reported a dependency problem, but the available information is insufficient to determine whether it affects this extension in practice.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-8fgc-7cc6-rx7x to a dependency declared by this repository.

Contextual assessment: The low scanner severity is not enough to establish practical risk. No package, version, vulnerable code path, attacker input, or concrete harm is provided.

Impact: low · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory applicability, then upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-8fgc-7cc6-rx7x
File role
production
Source
package-lock.json

Dependency advisory GHSA-xvcm-6775-5m9r applies

Material concern · low confidence

A scanner found a known issue in a dependency, but the evidence does not establish whether this project uses the affected behavior.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-xvcm-6775-5m9r to a dependency declared by this repository.

Contextual assessment: The high-confidence scanner result lacks the dependency name, resolved version, vulnerable range, runtime reachability, attacker control, and resulting impact.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory applicability, then upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-xvcm-6775-5m9r
File role
production
Source
package-lock.json

Dependency advisory GHSA-3v7f-55p6-f55p applies

Material concern · low confidence

A scanner reported a dependency weakness, but the supplied evidence does not reveal whether it is reachable or harmful here.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.

Contextual assessment: The advisory match alone does not establish runtime exposure. Package identity, version, code path, input source, and concrete consequences are missing.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory applicability, then upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3v7f-55p6-f55p
File role
production
Source
package-lock.json

Dependency advisory GHSA-4c8g-83qw-93j6 applies

Material concern · low confidence

A scanner found a known issue in a dependency, but there is not enough detail to tell whether users are exposed through this extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.

Contextual assessment: No affected dependency, resolved version, vulnerable function, runtime reachability, attacker-controlled input, or concrete impact is supplied.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory applicability, then upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4c8g-83qw-93j6
File role
production
Source
package-lock.json

Dependency advisory GHSA-5p4m-2wfm-xmqj applies

Material concern · low confidence

A scanner reported a dependency issue, but the evidence does not show whether this project can trigger it or what damage it could cause.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-5p4m-2wfm-xmqj to a dependency declared by this repository.

Contextual assessment: The high scanner severity is not independently actionable without package identity, installed version, advisory applicability, runtime reachability, and impact analysis.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory applicability, then upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-5p4m-2wfm-xmqj
File role
production
Source
package-lock.json

Dependency advisory GHSA-f886-m6hf-6m8v applies

Material concern · low confidence

A scanner found a dependency weakness, but the supplied information cannot determine whether it affects normal use of this extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.

Contextual assessment: The medium scanner severity does not establish practical exposure. Affected package, version, reachable code, attacker input, and concrete harm are omitted.

Impact: low · Exploitability: plausible

Developer action: Identify the affected package and installed version, confirm runtime reachability and advisory applicability, then upgrade or constrain it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f886-m6hf-6m8v
File role
production
Source
package-lock.json

Dependency advisory GHSA-52cp-r559-cp3m applies

Material concern · low confidence

A scanner found a high-severity issue in a dependency, but the supplied evidence does not identify which dependency or show whether the affected code is used.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m to a dependency declared by this repository.

Contextual assessment: The advisory match is high severity, but package identity, installed version, vulnerable component, runtime reachability, attacker-controlled input, and concrete impact were removed. The lockfile excerpt only establishes that the project has one production dependency and many development dependencies; it does not support a more specific conclusion.

Impact: high · Exploitability: plausible

Developer action: Provide the matched package name, installed version, advisory details, and runtime reachability so the dependency can be assessed and updated if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-52cp-r559-cp3m
File role
production
Source
package-lock.json

Dependency advisory GHSA-3ppc-4f35-3m26 applies

Material concern · low confidence

A scanner found a high-severity issue in a dependency, but there is not enough information to know whether it affects users of this extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.

Contextual assessment: Only an advisory identifier and scanner classification are supplied. The dependency, version, vulnerable behavior, reachability, and attacker prerequisites are unavailable, so immediate exploitation cannot be established.

Impact: high · Exploitability: plausible

Developer action: Provide the matched package name, installed version, advisory details, and runtime reachability so the dependency can be assessed and updated if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3ppc-4f35-3m26
File role
production
Source
package-lock.json

Dependency advisory coverage is insufficient

material risk · low confidence

Seven dependency warnings were reported, but the supplied report removed the details needed to tell which packages are affected or whether the problems reach users. This is a coverage limitation requiring dependency and source review.

Technical assessment

The evidence is text metadata and a short lockfile excerpt. It confirms scanner matches but omits package details and does not expose enough lockfile or application source to determine resolved versions, production reachability, attacker control, or concrete impact.

Impact: high · Exploitability: plausible

Developer action: Supply the complete matched package names and resolved versions, advisory descriptions, dependency paths, and relevant runtime call sites; then upgrade or constrain affected production dependencies and regenerate the lockfile.

Sources:

Dependency advisory GHSA-mh99-v99m-4gvg applies

Material concern · low confidence

The scanner reports a high-severity dependency problem, but the available information cannot show how it could affect this extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.

Contextual assessment: The evidence lacks the affected package and resolved version, vulnerability type, runtime use, attacker-controlled path, and resulting harm. The scanner result warrants follow-up but not a high-confidence immediate-danger finding.

Impact: high · Exploitability: plausible

Developer action: Provide the matched package name, installed version, advisory details, and runtime reachability so the dependency can be assessed and updated if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg
File role
production
Source
package-lock.json

Dependency advisory GHSA-c2c7-rcm5-vvqj applies

Material concern · low confidence

A high-severity dependency warning was reported, but the evidence does not identify the affected software or demonstrate user impact.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.

Contextual assessment: The advisory match is uncontextualized: package identity, installed version, vulnerable code path, reachability, and exploitation conditions are absent. Assessment remains provisional.

Impact: high · Exploitability: plausible

Developer action: Provide the matched package name, installed version, advisory details, and runtime reachability so the dependency can be assessed and updated if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-c2c7-rcm5-vvqj
File role
production
Source
package-lock.json

Dependency advisory GHSA-48c2-rrv3-qjmp applies

Material concern · low confidence

A medium-severity dependency warning was reported, but it is unclear whether the affected code runs in the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-48c2-rrv3-qjmp to a dependency declared by this repository.

Contextual assessment: The supplied metadata does not identify the package, resolved version, advisory weakness, runtime reachability, attacker input, or concrete consequence. The medium scanner rating supports remediation review, not a definitive impact determination.

Impact: medium · Exploitability: plausible

Developer action: Provide the matched package name, installed version, advisory details, and runtime reachability so the dependency can be assessed and updated if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-48c2-rrv3-qjmp
File role
production
Source
package-lock.json

Dependency advisory GHSA-38r7-794h-5758 applies

Material concern · low confidence

A low-severity dependency warning was reported, but the evidence does not show whether it matters to the shipped extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-38r7-794h-5758 to a dependency declared by this repository.

Contextual assessment: The package and version are unavailable, as are the vulnerable operation, runtime reachability, attacker control, and effect. The finding cannot be reduced to a confirmed low-risk issue from scanner metadata alone.

Impact: low · Exploitability: plausible

Developer action: Provide the matched package name, installed version, advisory details, and runtime reachability so the dependency can be assessed and updated if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-38r7-794h-5758
File role
production
Source
package-lock.json

Dependency advisory GHSA-rgw5-rvv9-x895 applies

Material concern · low confidence

A high-severity dependency warning was reported, but there is not enough detail to determine whether users are exposed.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.

Contextual assessment: Only the advisory identifier and scanner severity are present. The affected dependency/version, vulnerable code reachability, attacker-controlled input, and concrete harm are unknown, preventing a high-confidence conclusion.

Impact: high · Exploitability: plausible

Developer action: Provide the matched package name, installed version, advisory details, and runtime reachability so the dependency can be assessed and updated if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895
File role
production
Source
package-lock.json
Expected scanner matches (10)

JavaScript analysis reported javascript.xray.prototype-pollution

Expected behavior · high confidence

This signal is in compiler-generated helper code for defining class properties, not evidence that the extension is changing unrelated object behavior.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.prototype-pollution in this repository.

Contextual assessment: The supplied context shows transpilation helpers using property-definition and prototype operations typical of generated JavaScript. No attacker-controlled property path or security-sensitive object mutation is demonstrated.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.prototype-pollution
File role
generated
Source
dist/index.js:274

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The flagged environment access only selects whether the build is minimized for production. It does not collect or transmit credentials.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.

Contextual assessment: The cited line reads NODE_ENV to configure webpack optimization. No serialization, credential access, persistence, or network destination is shown.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.serialize-environment
File role
tooling
Source
webpack.config.cjs:62

JavaScript analysis reported javascript.download-to-execution

Expected behavior · low confidence

The available evidence shows a client extension that manages MCP servers, but it does not show downloaded content being executed by this extension.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: The scanner reports network retrieval correlated with an execution sink, but the supplied source window does not identify either the retrieval destination, the sink, their data flow, or execution timing. The stated purpose includes connecting to user-configured MCP servers, so the generic correlation is insufficient to establish a vulnerability or malicious behavior.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.download-to-execution
File role
generated
Source
dist/index.js:1

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

This environment check controls source-map generation during development and does not expose user information.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.

Contextual assessment: The cited expression reads NODE_ENV to select a webpack devtool setting. It has build-time configuration semantics and no outbound data flow.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.serialize-environment
File role
tooling
Source
webpack.config.cjs:34

JavaScript analysis reported javascript.xray.prototype-pollution

Expected behavior · high confidence

This is another match in standard generated support code for iterators and classes, rather than a demonstrated attack path.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.prototype-pollution in this repository.

Contextual assessment: The bounded context consists of transpiler/runtime helper logic, including iterator handling and object property operations. It does not establish prototype pollution through attacker-controlled input.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.prototype-pollution
File role
generated
Source
dist/index.js:716

JavaScript analysis reported javascript.xray.prototype-pollution

Expected behavior · high confidence

The flagged code is duplicated or nearby compiler-generated helper code and does not show harmful object manipulation.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.prototype-pollution in this repository.

Contextual assessment: The evidence shows Babel-style helpers for class construction, symbol conversion, and property definition. No data flow from network or user input into a prototype key or privileged sink is supplied.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.prototype-pollution
File role
generated
Source
dist/index.js:267

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The environment value determines whether TypeScript checking is strict during the build; it is not a secret-reading operation.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.

Contextual assessment: The cited code uses NODE_ENV to set ts-loader transpileOnly. This is ordinary build behavior without credential serialization or transmission.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.serialize-environment
File role
tooling
Source
webpack.config.cjs:54

JavaScript analysis reported javascript.xray.prototype-pollution

Expected behavior · high confidence

The flagged line is compatibility code generated by a JavaScript transpiler for generator functions. It is not evidence that the extension is modifying unrelated objects or executing attacker-controlled data.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.prototype-pollution in this repository.

Contextual assessment: The candidate points to a fallback assignment of a generator function's prototype property in transpiled runtime support. The code first uses Object.setPrototypeOf when available and only assigns the equivalent prototype property for older environments; no external input, persistence, credential handling, or suspicious destination is shown in the supplied context. This is a common generated-runtime pattern rather than demonstrated prototype-pollution behavior in application logic. In addition, the stated MCP client purpose makes MCP integration and configured server communication contextually relevant, but that behavior is not implicated by this line itself.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.prototype-pollution
File role
generated
Source
dist/index.js:2365

JavaScript analysis reported javascript.xray.prototype-pollution

Expected behavior · low confidence

The scanner found a generic JavaScript pattern, but the supplied evidence does not show that an attacker can use it to alter the extension or run harmful actions.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.prototype-pollution in this repository.

Contextual assessment: The JS-X-Ray result retains neither the matched literal nor a relevant code location beyond the generated-file boundary. No attacker-controlled input, unsafe merge path, prototype mutation, or reachable execution consequence is demonstrated.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.prototype-pollution
File role
generated
Source
dist/index.js:1

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The build uses an environment setting to choose development or production mode. This does not send the environment contents anywhere.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.

Contextual assessment: The cited expression compares NODE_ENV and selects webpack mode. No environment serialization or external destination is present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.serialize-environment
File role
tooling
Source
webpack.config.cjs:5

Coverage and limitations

JavaScript coverage

Unresolved JavaScript stages

Tools

Limitations

Technical scan identity